What is CVE-2026-13170?
This vulnerability affects The Eventin WordPress plugin before version 4.1.20. Due to improper validation of a template path setting, users with editor-level access and above can include and execute arbitrary local PHP files. It is highly recommended to update the plugin to version 4.1.20 immediately.
Azərbaycanca: Bu zəiflik WordPress üçün Eventin plagininin 4.1.20-dən əvvəlki versiyalarına təsir edir. Problem şablon yolunun düzgün yoxlanılmaması səbəbindən redaktor və daha yüksək səviyyəli istifadəçilərə ixtiyari lokal PHP fayllarını daxil edib icra etməyə imkan verir. Dərhal plagini ən son 4.1.20 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which plugin is affected by CVE-2026-13170?
CVE-2026-13170 affects The Eventin WordPress plugin in versions prior to 4.1.20.
Who can exploit this vulnerability?
Users with editor-level access and above can exploit the improper validation of the template path setting to include and execute arbitrary local PHP files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.